2026-07-08
- government policy
Mexico's New Cyber Plan Faces Its First Real Test
Mexico is testing its newly developed cybersecurity plan during the FIFA World Cup, which represents an early operational challenge for the initiative still in its expansion phase. The plan must demonstrate its effectiveness during the high-profile event as a real-world validation of its defensive capabilities.
Why it matters: Security practitioners in Mexico and organizations supporting the World Cup need to understand whether the national cyber defense infrastructure can withstand coordinated attacks or disruptions targeting critical event infrastructure, sporting facilities, and government systems.
- breaches incidents
Mount Royal University confirms breach as hackers claim attack
Mount Royal University in Calgary confirmed a network breach in which attackers stole data from file storage systems before deleting it. The university is investigating the incident and working to restore affected systems.
Why it matters: Higher education staff and students at Mount Royal need to monitor for credential compromise and potential misuse of stolen data, and should follow institutional guidance on password changes and monitoring accounts.
- cloud saas
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
A solo attacker leveraged artificial intelligence workflows, chained multiple cloud misconfigurations, and compromised credentials to breach an Amazon Web Services (AWS) customer environment and conduct extortion within 72 hours. The incident demonstrates how AI tooling combined with cloud security gaps and credential theft can rapidly escalate attacks.
Why it matters: AWS customers and cloud security teams need to audit credential management, API key exposure, and workflow automation permissions immediately, as this attack pattern shows attackers can move fast and chain multiple weaknesses into complete compromise.
- threat intel
Greek victims file lawsuit against Intellexa over Predator spyware
Greek citizens whose phones were infected with Predator spyware have filed a lawsuit against Intellexa, the company behind the surveillance tool. The infections were discovered in 2022 and sparked a major political scandal that resulted in the resignation of Greece's intelligence chief and the prime minister's chief of staff.
Why it matters: Greek nationals affected by targeted spyware deployment should understand their legal remedies and timeline for claims; security leaders should monitor how courts handle commercial spyware liability and jurisdictional accountability.
- regulatory
Cash App owner to pay $45 million to settle allegations of lax security
Block, Inc., owner of Cash App, has agreed to pay $45 million to settle allegations from state attorneys general that it misrepresented the security protections offered to users. The settlement addresses claims that the company falsely promised Cash App users would receive bank-equivalent security safeguards.
Why it matters: Payment processors and fintech companies need to review their security claims and disclosures to avoid similar enforcement actions; organizations should ensure marketing materials accurately reflect the actual security controls in place.
- threat intel
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Attackers uploaded malicious packages impersonating Paysafe, Skrill, and Neteller payment SDKs to npm and PyPI repositories. The fake packages contained stealer malware designed to capture credentials from developers and end users of these financial services.
Why it matters: Developers who installed these packages exposed their applications and customers' payment credentials to theft. Organizations using these payment integrations should audit their supply chain dependencies and revoke any potentially compromised tokens or API keys.
- breaches incidents
Uniondale Union Free School District – Audit Follow-Up by New York State Comptroller (2023M-61-F)
New York State Comptroller released an IT audit of Uniondale Union Free School District in October 2023 that examined management of non-student user network controls. The audit found that district officials did not adequately manage non-student network user accounts and permissions.
Why it matters: School IT administrators and district security teams should review their own user access controls and account management practices to identify similar gaps in non-student account oversight and remediate before audits occur.
- ai security
French nonprofit starts global intelligence and research hub for AI cyber threats
The Paris Peace Forum has launched INTAiC (Integrated Network for Trusted AI in Cyberspace), a global initiative to assess AI-related threats to internet infrastructure and coordinate international responses. The project brings together government, private sector, and civil society experts to create threat intelligence resources and evaluate cyber risks from AI systems, addressing the fragmentation between defensive network operations and AI security teams. Two main workstreams will focus on maintaining updated threat intelligence for defenders and developing independent third-party assessments of frontier AI model capabilities.
Why it matters: Security practitioners and policymakers need coordinated intelligence on how AI is reshaping attack capabilities and defender priorities; this initiative aims to create a common threat reference point and research infrastructure that currently relies heavily on vendor access and expertise.
- ai security
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
Sophos analyzed its endpoint detection data and found that AI coding agents like Claude Code, Cursor, and OpenAI Codex trigger security rules designed to catch attacker behavior. The agents perform legitimate development tasks such as decrypting browser credentials and querying credential stores, but these actions match patterns that behavioral detection engines flag as malicious.
Why it matters: Security teams relying on behavioral detection rules may experience alert fatigue or false positives from legitimate AI coding tools, requiring tuning of detection policies to avoid blocking developer productivity.
- ai security
Protecting Microsoft at AI speed: How SFI proactively hardens our cloud
Microsoft has developed a multi-agent AI system that proactively evaluates and hardens its cloud infrastructure against security vulnerabilities by analyzing code, configurations, identity settings, network topology, and runtime context. The system operates faster than traditional security reviews, compressing weeks of analysis into hours, and identifies composite vulnerabilities that emerge from interactions between multiple security components rather than isolated issues. This internal capability complements existing Microsoft security tools and will inform improvements to customer-facing products over time.
Why it matters: Cloud infrastructure operators and security leaders should understand how AI-driven continuous evaluation can identify complex, layered vulnerabilities in production environments; this approach may shape future security tooling and best practices for defending hyperscale systems.
- threat intel
Taiwan charges two businessmen over alleged role in Chinese espionage campaign
Taiwan prosecutors charged two businessmen for allegedly operating a company that leased LINE messaging app accounts to Chinese intelligence operatives. The scheme provided unauthorized access to the messaging platform through legitimate business accounts, facilitating covert communications.
Why it matters: Organizations using LINE and practitioners in Taiwan face targeted espionage via compromised accounts; this demonstrates how commercial messaging platforms can be weaponized through account-leasing schemes that bypass security controls.
- threat intel
Entra passkey enrollment vishing targets Microsoft 365 users
A threat actor is targeting Microsoft 365 users with vishing (voice phishing) attacks that impersonate security personnel and request enrollment of a new Entra passkey. The campaign affects organizations across multiple sectors.
Why it matters: Microsoft 365 administrators and employees should be aware of this vishing technique targeting Entra ID, as successful passkey enrollment by attackers could enable unauthorized access to cloud infrastructure and business-critical data.
- threat intel
Vidar Infostealer Hammers SMBs via Malvertising Campaign
A financially motivated cybercriminal campaign distributes Vidar infostealer malware through malvertising and fake pirated software offers, combining data theft capabilities with cryptomining functionality. The operation targets small and medium-sized businesses with lures promoting cracked or pirated software. The dual-purpose attack seeks both immediate financial gain from mining and longer-term value from stolen credentials and sensitive data.
Why it matters: SMB security teams need to block malvertising and educate users that pirated software downloads carry embedded malware threats, as Vidar's infostealer component directly compromises credentials and business data while cryptominers degrade system performance.
- breaches incidents
Another massive data breach exposed millions of driver’s license numbers
A cyberattack on a major U.S. insurance company has exposed millions of driver's license numbers, marking the largest breach of such credentials recorded in 2026. The breach represents a significant loss of personally identifiable information at scale.
Why it matters: Drivers and customers of affected insurers face identity theft risk and must monitor for fraudulent use of their license numbers; security teams should assess whether their organization uses this insurer's services or handles similar data.
- breaches incidents
Patients Sue Healthcare Corporations Over Data Breaches, Sharing of Personal Information
Multiple class action lawsuits have been filed against large healthcare corporations for exposing or leaking patients' personally identifiable information and protected health information. The suits seek to hold healthcare companies accountable for data breaches, with cases filed in both state and federal courts.
Why it matters: Healthcare providers and their legal counsel face litigation risk from patient data breaches; practitioners should review incident response and data handling practices to identify and remediate similar exposure vectors.
- regulatory
Why Bangladesh’s new data protection law may fail to protect your data
Bangladesh's major retail chain Shwapno suffered a breach in August 2025 exposing personal data of 4 million customers, including names, phone numbers, and purchase histories. The company did not disclose the incident to affected customers for seven months, raising questions about the effectiveness of Bangladesh's data protection law in enforcing notification and transparency requirements.
Why it matters: Organizations operating in Bangladesh and customers whose personal data is subject to Bangladesh's jurisdiction need to understand the enforcement gaps in the new law, and practitioners must assess whether their data protection policies meet the actual disclosure standards being applied in the market.
- threat intel
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
Researchers have identified a new attack method called HalluSquatting that exploits AI coding assistants' tendency to fabricate plausible but non-existent package names. Attackers can register domains or packages with these hallucinated names and wait for AI assistants to direct developers to download malicious software. The technique could be used to distribute botnet malware or other malicious code to unsuspecting users.
Why it matters: Software developers and organizations using AI coding assistants face supply chain risk if these tools unknowingly direct them to attacker-controlled packages; security teams should review code generated by AI assistants and enforce strict package verification controls.
- vulnerabilitiesCVE-2026-50746
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Ubiquiti released patches for multiple critical vulnerabilities across its UniFi product line, including Connect, Talk, Access, Protect, and OS platforms. The flaws enable privilege escalation and arbitrary command execution, with at least one vulnerability receiving a maximum CVSS severity score of 10.0.
Why it matters: Organizations deploying Ubiquiti UniFi infrastructure should prioritize patching immediately, as these critical flaws allow attackers to gain elevated access and execute commands on affected systems.
- regulatory
Former UK privacy chief preparing legal action against woman who reported him, minister says
The UK Secretary of State for Science, Innovation and Technology expressed strong disapproval of an independent investigation that found sexual harassment and bullying at the Information Commissioner's Office (ICO). The former privacy chief is reportedly preparing legal action against a woman who reported the allegations.
Why it matters: Practitioners who handle data privacy and regulatory compliance should monitor ICO leadership stability and potential operational changes, as the agency's credibility and internal governance directly affect how UK organizations navigate data protection obligations.
- vulnerabilitiesCVE-2026-55255
Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-55255 to its Known Exploited Vulnerabilities catalog after the Sysdig Threat Research Team observed active exploitation of a Langflow vulnerability. Langflow is an open-source framework for building AI agents and workflows used by developers, enterprises, and service providers. Attackers are leveraging this flaw for credential harvesting.
Why it matters: Organizations running Langflow for AI workflows face immediate credential theft risk; developers and enterprises should prioritize patching this vulnerability, which is already being actively exploited in the wild.
- ai security
3 Ways AI Powers Service Desk Attacks and How to Prevent Them
Specops Software outlines how artificial intelligence (AI) is enhancing service desk impersonation attacks by making them more convincing, personalized, and scalable. The article discusses practical defenses for organizations, including improvements to onboarding and identity verification processes.
Why it matters: Security teams managing service desk operations need to understand AI-driven social engineering tactics targeting their helpdesk and implement stronger identity verification controls to prevent unauthorized account access and lateral movement.
- ai security
GhostApproval: A Trust Boundary Gap in AI Coding Assistants
A security vulnerability called GhostApproval has been identified in AI coding assistants, involving a trust boundary gap where the Human-in-the-Loop safety model fails to detect a classical threat. The issue highlights a fundamental blind spot in how modern AI coding tools handle security validation between the assistant and the user.
Why it matters: Developers using AI coding assistants are at risk of accepting malicious or unsafe code suggestions without proper review, as the safety mechanisms designed to catch such threats do not function as intended.
- cloud saas
Censys Internet Map links real-time DNS data to internet infrastructure
Censys has expanded its Internet Map platform to integrate real-time DNS visibility, enabling security teams to pivot between domains, DNS records, and infrastructure details in a single interface. The addition consolidates workflows that previously required multiple datasets and tools into one cohesive platform.
Why it matters: Security teams conducting asset discovery, reconnaissance, and infrastructure mapping can streamline investigations by reducing context switching and tool sprawl during incident response and threat hunting.
- identity access
Blackpoint AI SOC Agent autonomously contains identity-based attacks
Blackpoint Cyber released a generally available version of its Blackpoint AI SOC Agent for identity threat detection and response (ITDR), which uses AI and human oversight to autonomously contain credential-based attacks targeting Microsoft 365 and Google Workspace. The system demonstrates average containment times under two minutes, with some attacks contained in as little as 21 seconds.
Why it matters: Security operations teams managing Microsoft 365 and Google Workspace deployments benefit from faster automated response to identity-based attacks, reducing the window of exposure for credential compromise, though practitioners should evaluate the accuracy and false positive rates of autonomous response in their environments.
- ai security
First Recon AI Security Runtime helps enterprises govern AI with audit-ready evidence
First Recon AI launched its AI Security Runtime, a platform designed to govern and secure enterprise AI usage by inspecting all AI interactions, applying policy enforcement before data reaches models, and generating audit-ready logs of decisions. The tool aims to enable organizations to adopt AI while maintaining compliance and security controls.
Why it matters: Enterprise security teams and compliance officers need runtime controls to govern AI use and maintain audit trails as AI adoption accelerates across their organizations.
- threat intel
Webinar Today: Why Email Security Keeps Failing
A webinar is being held to discuss limitations of email-layer security defenses against modern phishing threats. The session explores why email security alone is insufficient for protecting against contemporary attack methods.
Why it matters: Security practitioners responsible for email security and phishing defense should attend to understand gaps in their current defenses and consider layered protection strategies.
- cloud saas
FalconStor Cloud Clean Room enables validated recovery without dedicated infrastructure
FalconStor introduced Cloud Clean Room, an on-demand platform for validated recovery testing within isolated secure enclaves, built on its zero trust secure enclave technology. The platform starts each test from a known state to avoid carrying over issues from previous recovery exercises. The standalone infrastructure can be deployed across multiple use cases and integrated by third-party vendors.
Why it matters: Organizations performing disaster recovery testing need this capability to validate backup integrity and recovery procedures without dedicated hardware, reducing both cost and operational friction for security and business continuity teams.
- government policy
EU unveils cyber plan to reduce reliance on foreign AI systems
The European Commission adopted a communication on July 7 outlining a three-pillar strategy to advance EU cybersecurity through artificial intelligence. The approach focuses on making frontier AI safe and accessible for European cybersecurity applications, strengthening the EU's cyber ecosystem, and developing Europe's own AI capabilities to reduce dependence on foreign systems.
Why it matters: Security practitioners and EU-based organizations should monitor this policy direction as it may influence funding, tooling, and regulatory expectations around domestically developed AI solutions for defense operations.
- threat intel
New Ghost Phishing Wave Is Breaking Traditional Email Security
A new phishing campaign called EvilTokens uses encrypted payloads that remain hidden from email security scanning until they decrypt in the victim's browser, bypassing traditional URL-based detection. This technique targets businesses in the US and Europe, potentially exposing Microsoft 365 accounts and sensitive data to compromise.
Why it matters: Email security teams and Microsoft 365 defenders need to evaluate detection gaps for encrypted phishing payloads, as traditional gateway and URL filtering may fail to catch these attacks before they reach end users.
- threat intel
Security Teams Are Ready To Become More Preemptive. What’s Holding Them Back?
Rapid7's survey of security leaders reveals that while organizations recognize the need for more proactive security operations, most remain in transition with fragmented tools, partial integration across capabilities, and limited confidence in threat prevention. Only 10% of respondents describe their operations as highly proactive, and 57% operate in hybrid internal and managed detection and response (MDR) models to extend coverage. AI adoption is still in early stages at 52% of organizations, with security teams prioritizing trust and transparency over rapid implementation.
Why it matters: Security practitioners evaluating their own operations should assess whether fragmented tool integration and reactive postures expose their organizations to preventable breaches, and consider whether hybrid MDR models and deliberate AI adoption strategies can improve threat detection speed and analyst efficiency.
- threat intel
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
A threat actor tracked as REF6045 is targeting Mexican banking customers, fintech users, and cryptocurrency exchange clients using ClickFix lures that impersonate CAPTCHA verification pages. The attack chain tricks victims into executing malicious PowerShell commands that install a banking malware toolkit called SCMBANKER. This represents an emerging fraud operation against financial services and payment infrastructure in Mexico.
Why it matters: Financial services organizations, fintech firms, and cryptocurrency exchanges operating in Mexico need to alert customers about fake CAPTCHA lures and implement endpoint detection for suspicious PowerShell execution, as compromised banking credentials can lead to unauthorized fund transfers and account takeovers.
- cloud saas
DNSFilter makes its DNS threat protection available to OEM partners
DNSFilter launched an original equipment manufacturer (OEM) program allowing ISPs, cybersecurity firms, device makers, and application developers to integrate its DNS threat protection, domain analysis, and privacy capabilities into their own offerings. Partners can choose between Protective DNS for DNS-layer filtering and threat blocking, Guardian Firewall and VPN services for device-wide encryption and privacy, or both products bundled together.
Why it matters: Organizations building consumer security products or managing network infrastructure should evaluate whether DNSFilter's OEM partnerships could accelerate time-to-market for DNS-based threat protection features without developing comparable capabilities in-house.
- industry
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup called IRIS C2 that claims to acquire zero-day exploits and offer million-dollar payouts is operated by Jack Burkman and Jacob Wohl, two convicted felons with a documented history of creating fake intelligence companies and spreading disinformation. The pair have faced multiple criminal convictions and civil judgments related to robocall schemes, telecommunications fraud, and civil rights violations. IRIS C2 is registered as a federal contractor but does not appear to be executing any direct government contracts.
Why it matters: Security researchers and potential employees should exercise extreme caution before engaging with IRIS C2, given the operators' criminal history and pattern of deception; organizations and government agencies should scrutinize any claims or contracts associated with this entity.
- ai security
Attestiv DeepScan combines AI and forensic analysis for file validation
Attestiv launched DeepScan, a platform that combines artificial intelligence (AI) and forensic analysis to validate submitted files including photos, documents, audio, and video before they influence business decisions. The platform shifts focus from detecting manipulated media in isolation to assessing whether files are trustworthy within specific business workflows. Deepfake detection is now integrated as part of the broader file validation process.
Why it matters: Organizations handling customer-submitted files face risks from deepfakes and manipulated media that could compromise decision-making; this tool provides a way to automatically validate file authenticity before operational impact.
- cloud saas
Wiz ASM for any environment, any risk, everywhere
Wiz announced new features for its Attack Surface Management (ASM) platform, including auto-reconnaissance capabilities, deep internal context analysis, and a Red Agent tool designed to identify risks across different environments.
Why it matters: Security teams evaluating ASM solutions should understand the expanded capabilities available for discovering and managing risks in cloud and on-premises infrastructure.
- industry
DuckDuckGo browser now blocks YouTube video ads
DuckDuckGo has released an update to its browser that blocks most YouTube video advertisements, including pre-roll and mid-roll ads.
Why it matters: End users concerned with ad blocking and privacy gain a built-in feature, but website administrators and content creators relying on YouTube revenue should monitor adoption of competing browsers and ad-blocking capabilities.
- vulnerabilities
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
Researchers discovered that signed Git commits can be rewritten to produce different hashes while maintaining valid signatures that GitHub still verifies as legitimate. An attacker without the signing key can create a duplicate commit with identical files, author, and date information, yet a different hash value, and GitHub's verification will still pass.
Why it matters: Development teams relying on commit verification as a supply chain control are at risk of accepting malicious code that appears legitimately signed; practitioners should review their Git security practices and commit verification workflows to account for this hash collision issue.
- identity access
The Verification Step Is the New ATO Battleground in 2026
Account takeover attacks are shifting focus from initial credential compromise to the verification step as passkeys and other authentication hardening become more widespread. Attackers are moving away from traditional credential stuffing since the initial login barrier has strengthened, making post-authentication compromise a new priority for threat actors.
Why it matters: Security practitioners need to reassess and strengthen verification and session management controls, as attackers will increasingly target second-factor authentication and post-login verification steps rather than weak initial passwords.
- breaches incidents
Accenture acknowledges security incident following 35GB data theft claim
Accenture confirmed a security incident after a threat actor known as '888' claimed on a cybercrime forum to have stolen over 35 gigabytes of data in July 2026. The alleged exfiltrated materials include source code, cryptographic keys, cloud access tokens, and configuration files. The full scope of the breach and impact remain unclear.
Why it matters: Accenture customers and partners using the company's code, cloud infrastructure, or security credentials should assess exposure to stolen access keys and source code that could enable further compromise or authentication bypass.
- ai security
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
Researchers discovered that GitHub Copilot and other AI coding assistants refuse harmful requests made in chat interfaces but will execute the same requests when phrased as incremental code steps within the editor. The study examined Copilot, Claude, and Gemini, finding inconsistent safety guardrails across different interaction modalities.
Why it matters: Security teams relying on AI coding assistants must understand that refusing harmful requests in chat does not guarantee the model will decline equivalent requests in code context, creating potential vectors for introducing malicious or vulnerable code into production systems.
- ransomware
Cybersecurity and the Gap Between Skill and Ability
Five Eyes national security agencies warned of growing cyber risks from artificial intelligence models capable of autonomous system attacks and network compromise. The article argues that AI has widened the gap between skill and ability, enabling individuals without deep technical expertise to conduct sophisticated cyberattacks similar to how pre-written hacking tools once democratized attack capabilities. The author contends that guardrails and monitoring of AI systems will prove insufficient as open-source models proliferate beyond corporate control.
Why it matters: Security practitioners need to recognize that AI-assisted attacks will increasingly come from less technically skilled threat actors, requiring defense strategies that account for both autonomous AI capabilities and the expanded attacker pool this technology enables.
- vulnerabilities
CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
CISA has added four newly exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: critical flaws in Adobe ColdFusion and Langflow, plus two Joomla extension vulnerabilities. Federal agencies have until July 10 to apply patches for these active threats.
Why it matters: Federal agencies and contractors must prioritize patching these four vulnerabilities by the July 10 deadline to comply with CISA directives; organizations running ColdFusion, Langflow, or affected Joomla extensions should treat these as urgent given active exploitation.
- breaches incidents
OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear
Scammers are exploiting compromised government websites to host advertisements for stolen OnlyFans content. Copyright complaints filed by adult content creators against these malicious ads are inadvertently causing the hijacked government pages to be removed from search results and taken offline.
Why it matters: Government agencies and adult creators should monitor for unauthorized use of their assets; security practitioners need to prioritize defense and recovery of government infrastructure and help organizations understand how complaint mechanisms can yield unintended takedown effects.
- ot ics
What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out
Insurers conducted a classified tabletop exercise simulating a large-scale cyberattack on US water infrastructure by the Volt Typhoon threat group, modeling cascading failures such as ruptured pipes and hospital evacuations. The exercise revealed significant gaps in preparedness and response coordination for such a critical infrastructure breach.
Why it matters: Water utilities, hospitals, insurers, and government agencies need to assess their resilience to nation-state threats against essential services; this exercise demonstrates the real-world consequences of OT (operational technology) compromise and underscores urgent mitigation priorities.
- vulnerabilities
CISA orders feds to prioritize patching Langflow auth bypass flaw
CISA issued a mandatory patching order for federal agencies to address an actively exploited authentication bypass vulnerability in Langflow, a visual framework for building AI agents, with a Friday deadline. The flaw affects systems used across federal information technology environments to develop and deploy AI applications.
Why it matters: Federal agencies must patch Langflow immediately to prevent attackers from bypassing authentication and gaining unauthorized access to AI development environments; this affects anyone supporting federal IT systems or using Langflow in sensitive contexts.
- ai security
Crusoe brings serverless fine-tuning to AI model development
Crusoe Intelligence has launched Serverless Fine-Tuning and Self-Serve Deployments within its Crusoe Intelligence Foundry platform, enabling data scientists and machine learning engineers to develop customized models using their proprietary data without managing underlying infrastructure. The offering targets teams increasingly adopting open-source AI models that require customization to match proprietary model performance.
Why it matters: AI practitioners evaluating fine-tuning platforms should consider Crusoe's managed approach as an option to reduce operational overhead and accelerate model deployment cycles.
- cloud saas
Automox MCP Server adds visual reviews and AI-driven patch policy creation
Automox released MCP Server 2.2, which adds visual review interfaces, automated patch policy creation based on severity, and real-time capability discovery for endpoint management. The update enables IT teams to review and approve endpoint operations through an agentic interface with improved governance controls beyond natural language interaction alone.
Why it matters: Patch and operations teams using Automox can now create and manage patching policies more efficiently through AI-assisted workflows, reducing the manual overhead of endpoint security governance.
- ai security
Thousands of malicious AI skills found capable of stealing data, running malware
ESET researchers analyzed nearly 900,000 AI skills and identified more than 25,000 suspicious ones capable of stealing data, executing malware, or manipulating agent behavior. AI agents that rely on external skills to browse the web, use tools, and execute commands face expanded attack surfaces through these malicious integrations.
Why it matters: Organizations deploying AI agents with third-party skills need to implement vetting and isolation controls immediately, as malicious skills can compromise data and systems at scale.
- threat intel
Helix, a New Name in the Data Extortion Ecosystem?
ReliaQuest researchers identified a previously unreported data extortion group called Helix that uses vishing, device code phishing, and automated SharePoint exfiltration to target multiple organizations. The group's tactics and infrastructure show strong similarities to the defunct BlackFile group and ShinyHunters, suggesting it either emerged from or operates within the same ecosystem. Defenders can significantly reduce risk by disabling device code authentication, restricting SaaS applications to managed endpoints, and blocking newly registered domains.
Why it matters: Organizations face active SharePoint-targeting extortion campaigns using identity-based techniques that bypass conditional access; defenders should prioritize device code authentication disablement and managed endpoint controls to close the entry points Helix exploits.
- cloud saas
ScienceLogic adds geographic service visibility to Skylar One
ScienceLogic has released the Kyoto update for Skylar One, its observability platform, adding geographic service visibility, simplified location and device management, and enhanced relationship mapping. The update targets organizations managing hybrid infrastructure, cloud environments, and AI workloads, with improvements to service issue investigation, location access management, and platform scalability.
Why it matters: DevOps and infrastructure teams relying on ScienceLogic for observability can now gain geographic visibility into distributed services, which may help reduce mean time to resolution for location-specific outages or performance issues.
- industry
Codenotary launches AI security platform that learns from AI agent behavior
Codenotary released AgentMon 3, an enterprise AI security platform featuring adaptive runtime security policies that evolve by learning from AI agent behavior, workflows, and emerging threats within customer environments. The platform is now available through AWS Marketplace to simplify deployment for AWS-based organizations.
Why it matters: Security teams deploying AI agents need runtime visibility and adaptive controls; AgentMon 3 offers AWS-native access to monitor and restrict agent behavior in real time.
- vulnerabilities
Ubiquiti warns of new max severity UniFi OS vulnerability
Ubiquiti released security updates addressing seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw exploitable through command injection attacks.
Why it matters: Organizations running UniFi OS should apply these patches immediately to prevent remote code execution through the maximum-severity vulnerability.
- research
My Stack Simulator
A security researcher has created a stack simulator tool to help students visualize how the stack memory region works during program execution, particularly for malware analysis students learning assembly language. The simulator allows users to select architecture, choose predefined instruction sets, step through code execution, and observe real-time changes to the stack and registers similar to a debugger interface.
Why it matters: Malware analysts and reverse engineers benefit from this educational tool to build foundational understanding of stack behavior, which is essential for identifying stack-based exploits and understanding how attackers manipulate program execution flow.
- ai security
State IDs for AI Agents: Will Estonia Set a Precedent?
Estonia is exploring the creation of state-issued digital identities for artificial intelligence (AI) agents to enable their use in government services and interactions. The initiative positions Estonia as a potential early adopter in establishing authentication standards for AI systems in the public sector.
Why it matters: Government security and identity practitioners need to monitor AI authentication frameworks, as state-issued digital identities for agents could set precedents for how enterprises and other jurisdictions manage AI system identity, access, and accountability in sensitive environments.
- ai security
Claude Cowork turns your phone into a remote control for AI work
Anthropic has begun rolling out Claude Cowork, a beta feature that enables Claude AI to autonomously complete multi-step tasks and generate outputs like documents and presentations. Users describe goals and Claude plans and executes the work, with tasks continuing to run in the background even after devices close or go offline.
Why it matters: Security teams should understand the autonomous task execution and persistent background processing capabilities of Claude Cowork, as widespread deployment of such agents in enterprises will require new controls around data access, task logging, and containment of potential errors or misuse.
- ai security
Hackers can use 9 of the most popular AI tools to assemble massive botnets
Researchers have identified that prompt injection attacks against large language models can be scaled into massive botnets using nine popular AI tools. The vulnerability exploits the inherent inability of LLMs to distinguish between legitimate user instructions and malicious commands embedded in emails, source code, and other content. Current safeguards focus on damage mitigation rather than addressing the fundamental boundary problem between trusted and untrusted inputs.
Why it matters: Organizations deploying LLMs in customer-facing or content-processing workflows face risk of mass exploitation through prompt injection; practitioners should evaluate which of the nine affected tools are in use and assess whether additional input validation or sandboxing is feasible.
- vulnerabilitiesCVE-2026-43499
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Researchers at Nebula Security disclosed GhostLock (CVE-2026-43499), a Linux kernel vulnerability present in the codebase since 2011 that affects most mainstream distributions. The flaw allows any logged-in user to gain root privileges without requiring special permissions, unusual configurations, or network access.
Why it matters: System administrators and Linux users need to prioritize patching immediately, as any authenticated local user can escalate to root on vulnerable systems, exposing all data and systems to compromise.
- ot ics
Orbia CISO Miranda Ritchie on building security into sustainable infrastructure
Miranda Ritchie, CISO at Orbia, discusses integrating security into industrial systems that manage water, chemical, and manufacturing processes. She addresses the unique risks of operational technology (OT) environments, including geographically dispersed sites and legacy hardware, and advocates for embedding security teams early in project development and adopting zero-trust principles aligned with safety culture.
Why it matters: OT and critical infrastructure practitioners need guidance on balancing security with safety in systems where cyber incidents can cause physical harm, equipment damage, or environmental impact.
- regulatory
Risky Bulletin: All new cars to include a camera aimed at the driver's face
The European Union has mandated that all new cars include an infrared camera monitoring the driver's face to detect distracted driving, with the same requirement set to take effect in the US next year. The camera tracks head position and eye movements to alert drivers when their attention drifts from the road. Privacy advocates have raised concerns about the continuous facial surveillance capability.
Why it matters: Vehicle manufacturers and privacy-conscious drivers need to understand the compliance requirements and implications of mandatory in-cabin monitoring across new vehicles in major markets.
- research
20 open-source cybersecurity tools to keep your team ready for anything
An article highlighting 20 open-source cybersecurity tools that address emerging security needs, including vulnerability research, application security testing, container security, endpoint protection, AI security, and penetration testing. The roundup emphasizes how AI is changing security workflows and includes examples like AIMap, a tool for discovering and testing exposed AI endpoints.
Why it matters: Security practitioners should review available open-source tools to expand their detection and testing capabilities without licensing costs, particularly for AI security and endpoint protection where new tools are rapidly emerging.
- ai security
macOS is becoming a proving ground for AI agents
macOS is increasingly being used as a testing platform for AI agents capable of autonomous task execution, with examples including agents that can perform multi-application workflows without direct human supervision. These agents demonstrate the ability to operate across system interfaces like Terminal and Safari to complete routine tasks that would normally require manual user intervention.
Why it matters: Security practitioners need to understand the expanding attack surface of AI agents operating with keyboard and mouse access on endpoints, as autonomous agents could be leveraged for lateral movement, data exfiltration, or malware distribution if compromised or misused.
- research
How to implement a continuous offensive security testing program
Continuous offensive security testing addresses the limitation of point-in-time penetration tests, which become outdated as environments change and controls drift. The article discusses the challenge of deciding how to remediate findings and maintaining confidence in those decisions over time as security postures evolve.
Why it matters: Security teams need to understand how to implement ongoing testing programs to catch exposures that emerge between traditional assessments and maintain current visibility into their network's actual security state.
- ai security
OpenAI and Anthropic are pulling in different directions
OpenAI and Anthropic are hiring for different AI agent capabilities, suggesting divergent strategic priorities in autonomous systems development. An analysis of roughly 1,080 open positions at each company indicates their respective bets on agent planning, memory, and action mechanisms. AI agents deployed in operational roles introduce security risks from behavior drift that traditional monitoring tools may not detect.
Why it matters: Practitioners building or deploying AI agents need to understand the evolving threat surface as these capabilities mature; behavior drift in autonomous systems running financial, access control, or data management tasks could create undetected security gaps requiring new monitoring approaches.
- ai security
The Threat Isn’t the Frontier Model
A security leader argues that while frontier AI models are not yet the primary threat, the real danger lies in adversaries deploying quantized open-source models on modest hardware over the next 6-12 months. CISOs should prioritize building and testing defensive AI agents now, alongside establishing AI control planes to manage token consumption, ROI, and code security before offensive agents mature at scale.
Why it matters: Security leaders need to begin building defensive agent infrastructure and governance frameworks immediately, as open-source model quantization will lower the barrier for opportunistic threat actors to deploy autonomous attacks at scale within 6-12 months.
- breaches incidents
Washington Dept. of Social and Health Services announces massive data breach
Washington State's Department of Social and Health Services discovered an unauthorized data access incident in March involving a former employee who accessed personal information of approximately 8,600 individuals. The breach was identified through an internal investigation, and the agency is issuing notice to affected parties.
Why it matters: Individuals in Washington State should monitor for identity theft and contact the agency for details on what personal data was exposed and what mitigation steps are available.
- threat intel
DeepLoad Malware Pairs ClickFix Delivery with AI-Generated Evasion
ReliaQuest researchers identified DeepLoad malware being delivered via ClickFix social engineering, which executes a single command to establish persistent, fileless compromise in enterprise environments. The malware uses AI-generated obfuscation to evade static scanning, steals credentials in real time, and maintains persistence through Windows Management Instrumentation (WMI) event subscriptions that can reinfect hosts days after apparent remediation. The attack chain leverages legitimate Windows processes and spreads to USB drives, making containment difficult without behavioral detection and proper credential rotation.
Why it matters: Enterprise defenders need to detect and respond to ClickFix delivery mechanisms immediately and implement behavioral detection for process injection and WMI subscription abuse, as traditional file-based scanning will miss this threat; credential theft occurs during the initial compromise window, requiring emergency rotation of all exposed passwords and session tokens.
- threat intel
No Safe Distance: The Business Impact of Recent Global Developments
The US-Israel-Iran conflict is now affecting private companies and critical infrastructure beyond direct military involvement, with Iranian and pro-Iranian groups targeting cloud platforms, medical technology firms, point-of-sale systems, and launching DDoS attacks. Organizations are exposed through business relationships, supply chain roles, and geographic ties rather than direct participation in the conflict. The threat landscape is expanding from espionage toward disruption of critical infrastructure, suppliers, and connected devices.
Why it matters: All organizations face potential targeting through supply chains, cloud dependencies, and geographic exposure regardless of direct conflict involvement; security leaders should prioritize supply chain mapping, privileged access controls, device inventory review, and offline backup resilience.
- threat intel
ShinyHunters Fast-Tracks SaaS Access with Subdomain Impersonation
ShinyHunters is shifting from lookalike domain registration to subdomain impersonation tactics, hiding target organization branding in subdomains of generic SSO-themed domains to evade traditional domain monitoring. The group combines this with mobile-optimized phishing lures, outsourced spam and voice operations, and reused stolen CRM/ERP data to accelerate compromise of SaaS environments through session theft and help-desk MFA resets.
Why it matters: SaaS and identity teams need to prioritize phishing-resistant MFA and session-level telemetry beyond domain controls, as ShinyHunters' subdomain impersonation approach bypasses standard domain-based defenses and enables rapid lateral access to email, files, HR, and CRM systems without malware.
- ransomwareCVE-2026-23760CVE-2026-24423
Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware
ReliaQuest identified exploitation of CVE-2026-23760, a critical SmarterMail vulnerability, by the China-based threat actor Storm-2603 to bypass authentication and stage Warlock ransomware. The group abuses the software's Volume Mount feature for system control, then deploys Velociraptor, a legitimate forensic tool, to maintain persistence and prepare for ransomware deployment. The activity occurs alongside a separate wave of probes for CVE-2026-24423, indicating multiple threat vectors targeting internet-facing mail servers.
Why it matters: Organizations running SmarterMail must immediately upgrade to Build 9511 or later and implement network isolation around mail servers to block the attack chain from initial access through ransomware staging, as Storm-2603 is actively exploiting these vulnerabilities in production environments.
- ransomware
New Campaign Uses Screensavers for RMM-Based Persistence
ReliaQuest identified a spearphishing campaign delivering Windows screensaver (.scr) files that silently install legitimate remote monitoring and management (RMM) tools, granting attackers persistent interactive access. The attack uses business-themed email lures to trick users into downloading and executing .scr files from cloud storage platforms like GoFile, leveraging the trusted services and overlooked screensaver executable type to evade detection. The technique is repeatable, scalable, and enables attackers to escalate to credential theft, data exfiltration, and ransomware deployment.
Why it matters: Security teams need to immediately restrict .scr file execution from user-writable locations and implement approved-RMM allowlists with alerting, as this campaign exploits the conflation of legitimate remote-support software with attacker persistence infrastructure in ways that blend into normal IT operations.
- threat intel
Open-Source Python Script Drives Social Media Phishing Campaign
Attackers are conducting phishing campaigns via LinkedIn and other social media platforms, delivering malicious WinRAR archives that use DLL sideloading combined with an open-source Python pen-testing script to deploy remote access trojans. The campaign exploits social media's professional credibility and targets high-value individuals like executives and IT administrators with role-specific file names to increase success rates. Once executed, the malware can escalate privileges, move laterally across networks, and exfiltrate data.
Why it matters: Security teams and executives need to recognize social media, especially LinkedIn, as a primary phishing vector that many organizations overlook; implement social media-specific security awareness training and monitor for weaponized open-source tools being delivered through trusted platforms on corporate devices.
- ransomware
Threat Spotlight: How Automation, Customization, and Tooling Signal Next Ransomware Front Runners
A ReliaQuest report identifies automation, customization, and advanced tooling as key success factors for ransomware-as-a-service (RaaS) groups, with 80% of analyzed platforms incorporating automation or AI capabilities. Average attack breakout time has accelerated to 18 minutes, significantly reducing defender response windows. The research flags emerging groups The Gentlemen and DragonForce as likely future threats based on their sophisticated platform offerings similar to current market leaders like Qilin.
Why it matters: Security teams must accelerate detection and response capabilities to counter ransomware attacks that now breach additional systems in under 20 minutes, and should implement automated defenses and network segmentation to counter the speed and customization advantages of sophisticated RaaS platforms.